For the better part of a decade, Brussels was the city that Big Tech feared. The General Data Protection Regulation, adopted in 2016 and enforced from 2018, became the gold standard for privacy law worldwide, inspiring more than 150 countries to craft their own versions. The AI Act, finalised in 2024, was the planet's first comprehensive attempt to regulate artificial intelligence by risk category. Together, these two landmark laws positioned the European Union as the undisputed global standard-bearer for rights-based digital governance, a regulatory superpower wielding what scholars call the “Brussels Effect” to shape corporate behaviour far beyond its borders.

That era may be ending. On 19 November 2025, the European Commission published its Digital Omnibus Package, a sweeping legislative proposal that amends the GDPR, the ePrivacy Directive, the AI Act, the Data Act, the Data Governance Act, and the NIS2 Directive in a single stroke. Framed as a necessary exercise in “simplification” and “competitiveness,” the package has drawn fierce opposition from an extraordinary coalition of civil society organisations, data protection authorities, privacy advocates, and digital rights groups who see it as something altogether different: a systematic dismantling of the very protections that made European digital law the envy of democracies everywhere.